PatchSiren cyber security CVE debrief
CVE-2026-15028 Red Hat CVE debrief
A flaw in libarchive allows remote attackers to trigger a heap overflow via a specially crafted tar archive, potentially leading to denial of service or arbitrary code execution. The issue arises during parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to system unavailability or attacker control. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- LOW 3.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-10
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-07-10
- Advisory updated
- 2026-09-22
Who should care
Defenders and administrators of systems handling tar archives, particularly those using libarchive, should assess exposure and prioritize remediation. System criticality should guide prioritization, and defenders should verify affected versions and systems. The vulnerability's impact on system availability and potential for arbitrary code execution necessitates prompt action.
Why it matters
CVE-2026-15028 is a heap overflow vulnerability in libarchive that could lead to denial of service or arbitrary code execution. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources.
- Potential denial of service, making systems unavailable
- Possible arbitrary code execution, allowing attacker control
- Need to verify affected versions and systems
- Remediation priority based on system criticality
Technical summary
The libarchive library is vulnerable to a heap overflow when parsing a specially crafted tar archive, specifically a PAX extended header with a malformed SUN.holesdata sparse-file attribute. This vulnerability could lead to denial of service or arbitrary code execution. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources. Affected product deployments need identification, and owners should be assigned for follow-up.
Defensive priority
Assess exposure and prioritize remediation for systems handling tar archives.
Recommended defensive actions
- Assess exposure of systems handling tar archives
- Prioritize remediation based on system criticality
- Verify vendor-provided patches and updates
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its impact and remediation require verification. Affected systems handling tar archives need assessment, and defenders should verify vendor-provided patches and updates. The vulnerability's exploitation could lead to denial of service or arbitrary code execution, emphasizing the need for prompt remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15028 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15028
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15028 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15028
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:38279
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-15028
-
Source reference
Unverified legacy reference
URL: https://github.com/libarchive/libarchive/issues/3251
-
Source reference
Unverified legacy reference
URL: https://github.com/libarchive/libarchive/pull/3253
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.